How some applications do not allow the administrator to close them?

I have "Kaspersky Endpoint Security 10" in my windows. In my place, it also has a server application, and if you want to close the application, you must enter the password that is defined on the server side.

By the way, if you want to close the application process ( avp.exe ) on the Task Manager or Resource Monitor (even if you were the administrator of the current PC and you ran these applications as administrator), the system reports that you do not have access to this. Task Manager Alerts:

 The Operation could not be completed. Access is denied. 

And the Resource Monitor reports:

 When attempting to execute the command, the following system error occurred: Access is denied. 

So why? Is there a level of access in Windows above the system administrator? If so, what is it and who gives it? And if not, what is this mistake? Does Kaspersky use any particular idea? What is this idea?

And finally, is it possible to add this feature to our applications?

+5
source share
1 answer

I have "Kaspersky Endpoint Security 10" in my windows.

I'm sorry.

Is there a level of access in Windows above the system administrator?

Yes, sort of. There is SYSTEM, which is a local machine and is not a real user with whom you can log in. However, as an administrator, you have the ability to set up services and tasks to run as SYSTEM (see, for example, PsExec, how to use this to get the system shell) and change permissions on files and processes belonging to SYSTEM, t is really a significant security margin here.

While you can get permission from the administrator, this is unlikely to be the only trick Kaspersky has. There is a constant arms race between malware and antivirus authors (*), each of which is trying to automate the removal of the other, so it would be common to see, for example, a constant rebellion that prevents you from actually getting rid of the process.

(* to the extent that there is a specific difference these days when AV can itself be spyware ...)

And finally, is it possible to add this feature to our applications?

Please no! This only annoys users and does not provide any real security.

+5
source

Source: https://habr.com/ru/post/1233031/


All Articles